Impact
The vulnerability is a heap-based buffer overflow within the Windows Link Layer Topology Discovery Protocol (LLTD) that allows an unauthenticated attacker to execute arbitrary code on the target system when a malicious network packet is processed. The flaw, catalogued as CWE‑122, can give the attacker full control over the affected machine without requiring local privileges, resulting in a high confidentiality and integrity breach.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2, and multiple Windows 11 releases (23H2, 24H2, 25H2, 26H1), as well as Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 in both regular and Server Core installations. The problem stems from the LLTD component present in all these editions.
Risk and Exploitability
The CVSS score of 8.1 classifies the issue as High, and the lack of an EPSS score indicates that usage-based metrics are unavailable; the vulnerability is currently not listed in the CISA KEV catalog. The vector relies on an attacker being able to send crafted LLTD traffic to a vulnerable host over the network. Because the flaw is remote and does not require local authentication, mitigation is urgent for any exposed systems.
OpenCVE Enrichment